All Apps and Add-ons

Why doesn't Splunk App for AWS show policy action logs for S3?

randalthor80
Engager

A coworker of mine was applying some policy changes to S3, and something went wrong. When he wanted to look at what happened, specifically the logs for S3 in splunk, he noticed that they weren't there.

Doesn't Cloudtrail store policy actions like that? If so, doesn't Splunk do it's magic with them?

0 Karma
1 Solution

randalthor80
Engager

You know, it helps if I were to read what AWS Cloutrail supports. As of now, it doesn't support S3 policies.

View solution in original post

0 Karma

randalthor80
Engager

You know, it helps if I were to read what AWS Cloutrail supports. As of now, it doesn't support S3 policies.

0 Karma
Get Updates on the Splunk Community!

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...

Observability Newsletter Highlights | March 2023

 March 2023 | Check out the latest and greatestSplunk APM's New Tag Filter ExperienceSplunk APM has updated ...

Security Newsletter Updates | March 2023

 March 2023 | Check out the latest and greatestUnify Your Security Operations with Splunk Mission Control The ...